SC-200 Manage a security operations environment Practice Question
You are configuring Microsoft Sentinel analytics rules. Which THREE of the following are valid types of analytics rules in Microsoft Sentinel?
⚠ Common exam trap
Candidates often confuse watchlists and playbooks with actual analytics rule types, as they are prominent features in Microsoft Sentinel but serve different purposes (data enrichment and automated response, respectively) rather than generating alerts or incidents.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Fusion rule
In Microsoft Sentinel, the analytics rule types available when creating a rule include Scheduled query rules (D), which run KQL queries on a defined frequency and trigger alerts based on results; Fusion rules (A), which use Microsoft's machine-learning correlation engine to detect multi-stage attacks across signals; and Microsoft Security rules (B), which create incidents from alerts generated by Microsoft security products like Defender and Microsoft 365. These three are the standard rule types offered in the Sentinel analytics rule wizard. Watchlist rule (C) is not a rule type — watchlists are data sources used to enrich queries and can be referenced inside scheduled rules, not a standalone analytics rule. Playbook rule (E) is also not a rule type — playbooks are Logic Apps used for automated response and are triggered by automation rules or analytics rules, not created as analytics rules themselves.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Fusion rule
Why this is correct
Fusion rules are the correct answer here because they represent a built-in analytics rule type that uses advanced machine learning to correlate multiple low-severity signals across data sources, detecting multi-stage attacks in near real-time. Existing note: Fusion rules use advanced detection; this applies directly to the question's analytics rule configuration context.
- ✓
Microsoft Security rule
Why this is correct
Microsoft Security rules are a distinct analytics rule type in Sentinel that automatically create incidents from alerts generated by Microsoft security products such as Microsoft Defender for Endpoint, Defender for Office 365, and Defender for Identity. They are not the answer to this specific question, but they are a valid analytics rule type when configuring incident creation from native security alerts.
- ✗
Watchlist rule
Why it's wrong here
Watchlist rules are not an analytics rule type; watchlists are static reference data stored in Sentinel that can be used to enrich or filter queries within analytics rules, not standalone scheduled queries or data source detections. During analytics rule configuration, you might select a watchlist as a lookup, but you cannot choose 'Watchlist rule' as the rule type.
- ✓
Scheduled query rule
Why this is correct
Scheduled query rules are the most common and fundamental analytics rule type in Sentinel; they run a KQL query at a configurable frequency and generate alerts or incidents based on query results, allowing full control over detection logic and threshold tuning. The existing note correctly states this is a common analytics rule type, making it a plausible but incorrect answer for the specific scenario in the question.
- ✗
Playbook rule
Why it's wrong here
Playbook rules are not an analytics rule type; playbooks are automated response workflows built on Azure Logic Apps that trigger in response to alerts or incidents, not detections themselves. During analytics rule creation, you configure the detection logic (like a scheduled query or Fusion rule), and optionally attach a playbook to automate remediation, but the playbook itself is not a rule type.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.